Term Kind Topic What it is
Client Feature Flags practice Client Feature Flags Flags evaluated in a browser or mobile app — where the constraints of distribution, caching and offline behaviour make them meaningfully harder than server flags.
Client State Architecture practice Client State Architecture Separating server state, client state and URL state — the distinction that removes most frontend complexity.
Cloud Disaster Recovery practice Disaster Recovery Designing and rehearsing recovery from the loss of a zone, a region or a provider — where the plan is worth exactly as much as its last test.
Cloud Exit Plan practice Multi-Cloud A documented, costed assessment of what leaving a provider or service would require — increasingly a regulatory expectation and a better lock-in control than portability itself.
Cloud Governance practice Cloud Governance The account structure, identity model, guardrails and cost attribution that make a cloud estate operable by many teams without becoming ungovernable.
Cloud Migration practice Cloud Migration Moving workloads to the cloud — where the strategy per workload matters more than the programme, and where lift-and-shift produces the bill that discredits the whole effort.
Cluster Architecture practice Cluster Architecture How many clusters, how they are divided, and what shares fate — decisions about blast radius and operational burden rather than about capacity.
Co-Change Analysis Change Coupling, Logical Coupling practice Service Boundaries Using version-control history to find which components change together - the strongest available evidence that a proposed boundary is right or wrong.
Code List Governance practice Reference Data Managing the small shared enumerations — currencies, country codes, statuses, product categories — whose uncontrolled change breaks systems quietly.
Code Review practice Code Review Peer inspection before merge — valuable for knowledge sharing and design feedback, and reliably harmful when it becomes a latency bottleneck.
Cold-Start Amortisation Warm Affinity, Startup Cost Reduction practice Serverless Attacking the startup cost itself - through snapshots, lazy image pulls, local artefact caches and affinity routing - rather than choosing between scaling strategies that all suffer from it.
Command Validity Window Command Expiry, Time-Bounded Actuation practice Fleet Management An expiry attached to a command sent to a device, so that an instruction delivered after the situation has changed is discarded rather than executed.
Communicating a Threat Model practice Communicating Threat Models Producing a threat model that engineers act on — structured by data flow, prioritised by risk, and expressed as work rather than as a report.
Communicating with Engineers practice Presenting to Engineers Earning technical credibility and giving guidance that engineers act on — which depends more on how the reasoning is shared than on whether it is correct.
Communication Capture Obligation Off-Channel Risk, Supervised Communications practice Records Retention & Legal Hold A duty to preserve and produce business communications, which fails whenever the compliant channel is less convenient than an available alternative - making channel design, not policy, the control that determi…
Compaction File Consolidation, OPTIMIZE, Small File Remediation practice File Formats & Compaction Rewriting many small data files into fewer larger ones, with sorting, as a required background process - because streaming ingestion produces small files continuously and a table without compaction degrades si…
Compensating Control practice Stakeholder Analysis A cheaper measure that reduces a risk enough to proceed, used deliberately and with an expiry, when the full control cannot be delivered in the available time.
Complementary User Entity Control CUEC, User Control Consideration practice Three Lines Model A control the service provider's auditor assumed the customer operates, so that a clean vendor opinion only holds for customers who are actually running it.
Completeness Indicator As-Of Metadata, Result Confidence Marker practice Streaming SLOs Metadata published alongside a streaming result stating how current it is and what proportion of expected input it reflects - so consumers can reason about staleness instead of assuming currency.
Compliance Framework SOC 2, ISO 27001, PCI DSS practice Security Architecture A published set of control requirements an organisation is assessed against, which turns security posture into evidence somebody else will check.
Compliance Obligation Mapping practice Regulatory Constraints Translating regulatory text into specific, testable technical requirements attached to the systems they apply to.
Compliance Scope Boundary Scope Reduction, Cardholder Data Environment practice PCI-DSS Scoping The set of systems subject to a compliance regime - determined by where regulated data flows, and reducible by architecture rather than by adding controls.
Component Contracts practice Component Contracts The interface a shared UI component presents — where the discipline is refusing options as much as providing them.
Component Library Versioning practice Design Systems Treating a design system as a versioned product with a compatibility policy and a deprecation process, because its consumers cannot all upgrade at once.
Composed Page Budget Aggregate Performance Budget, Whole-Page Budget practice Micro-Frontends A performance budget enforced on the assembled page rather than per independently-owned fragment - because in a composed frontend nobody owns the total that users experience.
Compute Optimisation practice Compute Optimisation Reducing compute spend through sizing, scheduling, purchasing model and architecture — in increasing order of both effort and payoff.
Configuration Drift Detection practice IaC Modules & Drift Continuously comparing declared infrastructure against what actually exists, so out-of-band change is found on a Tuesday rather than during a rebuild.
Conflatable Classification Superseding vs Discrete Events, What May Be Dropped practice Device Telemetry at Scale Explicitly classifying each telemetry stream as superseding or discrete, because conflation is the correct overload behaviour for one and silent data loss for the other.
Conformance Automation practice Architecture Compliance Checks Encoding architectural standards as automated checks, so review effort is spent on novel design decisions rather than on verifying known rules.
Connection Draining Deregistration Delay, Graceful Shutdown practice Load Balancing Allowing in-flight requests on an instance to complete before it is removed from service, rather than terminating them at cutover.
Connection Pool Sizing practice Connection Pooling Choosing how many concurrent connections a service holds to a datastore, where both too many and too few cause outages.
Consent Management practice Privacy Engineering Capturing, storing, honouring and evidencing a data subject's permissions for specific processing purposes, including withdrawal.
Consent Propagation Consent Enforcement, Withdrawal Fanout practice Consent Architecture Carrying a consent decision - and especially a withdrawal - to every system and third party that processes on the basis of it, which is where most consent implementations fail.
Consequence-Based Tiering Proportionate Governance, Risk Tier by Impact practice AI Risk Tiering Assigning governance requirements according to the consequence of a system being wrong and who bears it, rather than by technology - so that the strictest controls apply where they matter and low-risk uses rem…
Consistency Choices practice Strong vs Eventual Consistency Deciding, per operation, the weakest consistency guarantee that is still correct — rather than choosing one model for a system.
Consistency Level Selection practice Strong vs Eventual Consistency Choosing the consistency guarantee per operation rather than per system, matching the cost of coordination to the business consequence of staleness.
Constraint Discovery practice Requirements to Constraints The systematic elicitation of the fixed conditions a solution must satisfy, distinguished from requirements because they are not negotiable and are rarely volunteered.
Constraint Expiry Dated Constraint, Constraint Provenance practice Requirements to Constraints Recording every constraint with its source and its expiry date, so that temporary facts do not get permanently encoded into an architecture.
Constraint Thinking practice Meta-Skills Designing for the budget, timeline, skills, regulations and existing estate that actually exist, rather than for the ones a textbook assumes.
Constraint Thinking practice Constraint Thinking Designing within the real limits — budget, skills, timeline, existing estate, organisational politics — rather than for the abstractly best answer.
Container Image Strategy Base Image Policy, Golden Image practice Container Image Strategy The organisational decision about where images come from, what they are built on, and how a base layer fix reaches everything already deployed.
Content Artefact Release Data-as-Release, Non-Code Release Engineering practice Artifact Management Applying full release engineering - versioning, staged rollout, health gates and a rollback path - to artefacts that are not code but are interpreted by privileged code, such as detection content, rule sets, m…
Content Purge Path Takedown Propagation, Cache Purge SLA practice Content Delivery Networks A separate, fast, fail-closed mechanism for removing content from every cache tier, which is what allows long TTLs everywhere else without making removal impossible.
Context Diagrams practice Context Diagrams The system, its users and everything it talks to — the cheapest, most durable and most under-used architecture artefact.
Context Map practice Bounded Contexts A diagram of the bounded contexts in a system and the relationship type between each pair, making integration expectations and power dynamics explicit.
Continuous Compliance practice Compliance Frameworks Producing compliance evidence automatically and continuously from the systems themselves, rather than reconstructing it before an audit.
Continuous Controls Monitoring CCM practice Continuous Controls Monitoring Automatically testing control effectiveness continuously across the whole population, rather than through periodic manual sampling.
Continuous Integration Discipline practice Continuous Integration Discipline The behavioural commitments that make CI a defect-detection system rather than a build server that runs tests.
Continuous Learning practice Continuous Learning Keeping judgement current in a field where the technologies change constantly and the fundamentals do not.
Continuous Profiling practice Profiling Sampling CPU, memory and lock profiles from production continuously at low overhead, so resource usage can be attributed to specific code paths.
Contract Enforcement Point Producer-Side Enforcement, Shift-Left Contract Checking practice Data Contracts Where a data contract is actually checked - which determines whether a breaking change fails in the producer's build or in a consumer's pipeline at 2 a.m.
Contract Testing Consumer-Driven Contracts practice Contract Testing Verifying that a provider satisfies what its consumers actually depend on, without deploying both together.
Contract Testing at Scale practice Contract Testing at Scale Operating consumer-driven contracts across hundreds of services, where the broker, versioning and deployment checks become the hard part.
Contract Verification Gate practice Contract Testing at Scale A provider's pipeline stage that replays every consumer's recorded expectations and fails the build if any would break.
Contributing Factors Analysis practice Postmortems Identifying the multiple conditions that combined to produce an incident, in place of searching for a single root cause.
Control Test Automation practice Continuous Controls Monitoring Executing a control's test continuously against the whole population rather than sampling it annually, which changes both the detection latency and the strength of the evidence.
Coordination-Cost Metric Services Per Change, Teams Per Feature, Lockstep Ratio practice EA Metrics The number of independently-owned services and teams that must change together for a typical feature - the clearest available signal that architectural boundaries are imposing delivery cost, and one almost nob…
Correlation ID practice Observability A single identifier attached to one logical operation and included in every log line it produces, anywhere in the system.
Cost Accountability Model practice Showback & Chargeback The arrangement determining whether teams merely see their costs or are financially charged for them, and the behaviour each produces.
Cost Allocation practice Cost Allocation Attributing spend to the team, service or customer that causes it — the prerequisite for every other cost conversation.